Use available evidence and guided answers.
Preview mode
Live connectors, billing, AI, and downstream writes are off. Your assessment workspace may still be saved when hosted persistence is active.
What this page does: The workbench helps answer assessment questions for the chosen framework/scope. ZAGOS uses answers and available evidence to identify gaps and prepare findings. Live connectors are parked until approved.
If no persisted scope exists, the page uses safe preview defaults.
You have answered 442 questions.
Your next safe step: Scroll down to answer questions or review scope.
Answered questions show readiness direction for your selected frameworks.
Unanswered questions become gaps or follow-up items. Live connector evidence remains parked until approved.
Results remain preview/guided unless durable persistence is explicitly enabled and saved by a workspace owner.
Answer coverage
442/442 answered (100%)
Readiness
60/100 readiness
Save location
This browser only
How is valid consent or another lawful basis obtained for biometric processing?
What are the retention and deletion practices for biometric templates?
Are there liveness detection or anti-spoofing controls (e.g. attacks using photos, masks, recordings)?
What is the primary purpose of the biometric processing?
Is the system used for remote biometric identification in publicly accessible spaces?
Which biometric modalities are used by the system?
Additional notes / context.
Additional notes / context.
Additional notes / context.
Additional notes / context.
Additional notes / context.
Describe the control/requirement and how it is implemented.
Evidence links / artifacts.
Is this tested and periodically reviewed?
Known failure modes and mitigations.
Residual risk
Additional notes / context.
Additional notes / context.
Additional notes / context.
Additional notes / context.
Additional notes / context.
Describe the control/requirement and how it is implemented.
Evidence links / artifacts.
Is this tested and periodically reviewed?
Known failure modes and mitigations.
Residual risk
Additional notes / context.
Additional notes / context.
Additional notes / context.
Additional notes / context.
Additional notes / context.
Describe the control/requirement and how it is implemented.
Evidence links / artifacts.
Is this tested and periodically reviewed?
Known failure modes and mitigations.
Residual risk
Additional notes / context.
Additional notes / context.
Additional notes / context.
Additional notes / context.
Additional notes / context.
Describe the control/requirement and how it is implemented.
Evidence links / artifacts.
Is this tested and periodically reviewed?
Known failure modes and mitigations.
Residual risk
Biometrics & Remote Identity: Describe the current state for this area.
Is there a named owner/accountable role for this area?
Known risks/issues and mitigations?
Maturity level
What evidence exists (policies, logs, reports, records)?
Biometrics & Remote Identity: Describe the current state for this area.
Is there a named owner/accountable role for this area?
Known risks/issues and mitigations?
Maturity level
What evidence exists (policies, logs, reports, records)?
Readiness score
60/100
Findings
232
Evidence gaps
449
0 weak
Workflows
8
What are the retention and deletion practices for biometric templates?
Collect retention_policy, data_flow_record, consent_record, system_inventory (owner: Data Protection Office).
Which biometric modalities are used by the system?
Collect consent_record, system_inventory (owner: Data Protection Office).
Is the service directly targeted at children or likely to be used by them?
Collect consent_record, policy_document (owner: Data Protection Office).
What are the main misuse / dual-use risks and how are they mitigated?
Collect policy_document, system_inventory (owner: AI Governance Lead).
Does the system implement logging that is sufficiently detailed to support traceability (Art. 12)?
Collect audit_log (owner: CISO / Security).
Is there a documented risk management framework for this AI system (Art. 9)?
Collect policy_document, system_inventory (owner: AI Governance Lead).
Summarise the controls in place for accuracy, robustness and cybersecurity (Art. 15).
Collect policy_document, system_inventory (owner: AI Governance Lead).
How are adverse decisions explained to customers (reasons, factors, rights to contest)?
Collect workflow_record, policy_document (owner: AI Governance Lead).
Ai risk assessment
33 questions need this.
Document human oversight
31 questions need this.
Renew supplier assurance
30 questions need this.
Classify ai system
26 questions need this.
Capture consent evidence
10 questions need this.
Access recertification
3 questions need this.
Publish retention schedule
1 questions need this.
Collect audit logs
4 questions need this.
No automated risks or tasks detected yet.